Executive brief
Home Assistant's frontend displays persistent notifications to users, which were vulnerable to cross-site scripting (XSS) attacks through specially crafted Markdown text. An attacker could inject malicious JavaScript code that executes in the context of a user's browser session, potentially stealing session cookies, session tokens, or performing actions on behalf of the user. This advisory has been withdrawn as the affected package could not be confirmed to have been published to npm.
Technical details
This vulnerability is a Stored XSS (Cross-Site Scripting) flaw in Home Assistant's frontend notification system, classified as CWE-79. The root cause was improper sanitization of Markdown output in persistent notifications, allowing an attacker to inject malicious JavaScript via crafted Markdown text. The attack requires no authentication and relies on user interaction (viewing a notification containing the malicious Markdown). An attacker can execute arbitrary JavaScript in the victim's browser within the Home Assistant application context, potentially compromising session data or account credentials. The vulnerability was fixed by upgrading to a safer Markdown parser (pagedown) that properly sanitizes output, implemented in version 0.57 and later.
Affected products
- Home Assistant Frontend < 0.57
Timeline
- 2017-11-10: disclosed
- 2017-10-27: patched: Fix merged via migration to pagedown markdown parser
- 2022-05-17: advisory
- 2023-10-10: other: Advisory withdrawn - package could not be confirmed as published to npm